Show filters
423 Total Results
Displaying 321-330 of 423
Sort by:
Attacker Value
Unknown

CVE-2021-42130

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
Attacker Value
Unknown

CVE-2021-42129

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
Attacker Value
Unknown

CVE-2021-42128

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
Attacker Value
Unknown

CVE-2021-42127

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
Attacker Value
Unknown

CVE-2021-42126

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
Attacker Value
Unknown

CVE-2021-42125

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
Attacker Value
Unknown

CVE-2021-42124

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
Attacker Value
Unknown

CVE-2021-22965

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.
Attacker Value
Unknown

CVE-2021-36235

Disclosure Date: September 01, 2021 (last updated November 28, 2024)
An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges.
Attacker Value
Unknown

CVE-2021-22933

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.